feat: add SMTP auth & TLS support (#13902)

This commit is contained in:
Danny Kopping
2024-07-19 09:22:15 +02:00
committed by GitHub
parent 8d4bccc612
commit 943ea7c52a
29 changed files with 1949 additions and 117 deletions
+15
View File
@@ -256,11 +256,26 @@ curl -X GET http://coder-server:8080/api/v2/deployment/config \
"notifications": {
"dispatch_timeout": 0,
"email": {
"auth": {
"identity": "string",
"password": "string",
"password_file": "string",
"username": "string"
},
"force_tls": true,
"from": "string",
"hello": "string",
"smarthost": {
"host": "string",
"port": "string"
},
"tls": {
"ca_file": "string",
"cert_file": "string",
"insecure_skip_verify": true,
"key_file": "string",
"server_name": "string",
"start_tls": true
}
},
"fetch_interval": 0,
+112 -5
View File
@@ -1700,11 +1700,26 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
"notifications": {
"dispatch_timeout": 0,
"email": {
"auth": {
"identity": "string",
"password": "string",
"password_file": "string",
"username": "string"
},
"force_tls": true,
"from": "string",
"hello": "string",
"smarthost": {
"host": "string",
"port": "string"
},
"tls": {
"ca_file": "string",
"cert_file": "string",
"insecure_skip_verify": true,
"key_file": "string",
"server_name": "string",
"start_tls": true
}
},
"fetch_interval": 0,
@@ -2107,11 +2122,26 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
"notifications": {
"dispatch_timeout": 0,
"email": {
"auth": {
"identity": "string",
"password": "string",
"password_file": "string",
"username": "string"
},
"force_tls": true,
"from": "string",
"hello": "string",
"smarthost": {
"host": "string",
"port": "string"
},
"tls": {
"ca_file": "string",
"cert_file": "string",
"insecure_skip_verify": true,
"key_file": "string",
"server_name": "string",
"start_tls": true
}
},
"fetch_interval": 0,
@@ -3072,11 +3102,26 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
{
"dispatch_timeout": 0,
"email": {
"auth": {
"identity": "string",
"password": "string",
"password_file": "string",
"username": "string"
},
"force_tls": true,
"from": "string",
"hello": "string",
"smarthost": {
"host": "string",
"port": "string"
},
"tls": {
"ca_file": "string",
"cert_file": "string",
"insecure_skip_verify": true,
"key_file": "string",
"server_name": "string",
"start_tls": true
}
},
"fetch_interval": 0,
@@ -3121,26 +3166,88 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
| `sync_interval` | integer | false | | The notifications system buffers message updates in memory to ease pressure on the database. This option controls how often it synchronizes its state with the database. The shorter this value the lower the change of state inconsistency in a non-graceful shutdown - but it also increases load on the database. It is recommended to keep this option at its default value. |
| `webhook` | [codersdk.NotificationsWebhookConfig](#codersdknotificationswebhookconfig) | false | | Webhook settings. |
## codersdk.NotificationsEmailAuthConfig
```json
{
"identity": "string",
"password": "string",
"password_file": "string",
"username": "string"
}
```
### Properties
| Name | Type | Required | Restrictions | Description |
| --------------- | ------ | -------- | ------------ | ---------------------------------------------------------- |
| `identity` | string | false | | Identity for PLAIN auth. |
| `password` | string | false | | Password for LOGIN/PLAIN auth. |
| `password_file` | string | false | | File from which to load the password for LOGIN/PLAIN auth. |
| `username` | string | false | | Username for LOGIN/PLAIN auth. |
## codersdk.NotificationsEmailConfig
```json
{
"auth": {
"identity": "string",
"password": "string",
"password_file": "string",
"username": "string"
},
"force_tls": true,
"from": "string",
"hello": "string",
"smarthost": {
"host": "string",
"port": "string"
},
"tls": {
"ca_file": "string",
"cert_file": "string",
"insecure_skip_verify": true,
"key_file": "string",
"server_name": "string",
"start_tls": true
}
}
```
### Properties
| Name | Type | Required | Restrictions | Description |
| ----------- | ------------------------------------ | -------- | ------------ | --------------------------------------------------------------------- |
| `from` | string | false | | The sender's address. |
| `hello` | string | false | | The hostname identifying the SMTP server. |
| `smarthost` | [serpent.HostPort](#serpenthostport) | false | | The intermediary SMTP host through which emails are sent (host:port). |
| Name | Type | Required | Restrictions | Description |
| ----------- | ------------------------------------------------------------------------------ | -------- | ------------ | --------------------------------------------------------------------- |
| `auth` | [codersdk.NotificationsEmailAuthConfig](#codersdknotificationsemailauthconfig) | false | | Authentication details. |
| `force_tls` | boolean | false | | Force tls causes a TLS connection to be attempted. |
| `from` | string | false | | The sender's address. |
| `hello` | string | false | | The hostname identifying the SMTP server. |
| `smarthost` | [serpent.HostPort](#serpenthostport) | false | | The intermediary SMTP host through which emails are sent (host:port). |
| `tls` | [codersdk.NotificationsEmailTLSConfig](#codersdknotificationsemailtlsconfig) | false | | Tls details. |
## codersdk.NotificationsEmailTLSConfig
```json
{
"ca_file": "string",
"cert_file": "string",
"insecure_skip_verify": true,
"key_file": "string",
"server_name": "string",
"start_tls": true
}
```
### Properties
| Name | Type | Required | Restrictions | Description |
| ---------------------- | ------- | -------- | ------------ | ------------------------------------------------------------ |
| `ca_file` | string | false | | Ca file specifies the location of the CA certificate to use. |
| `cert_file` | string | false | | Cert file specifies the location of the certificate to use. |
| `insecure_skip_verify` | boolean | false | | Insecure skip verify skips target certificate validation. |
| `key_file` | string | false | | Key file specifies the location of the key to use. |
| `server_name` | string | false | | Server name to verify the hostname for the targets. |
| `start_tls` | boolean | false | | Start tls attempts to upgrade plain connections to TLS. |
## codersdk.NotificationsSettings
+113 -2
View File
@@ -1212,7 +1212,7 @@ Which delivery method to use (available options: 'smtp', 'webhook').
| ----------- | -------------------------------------------------- |
| Type | <code>duration</code> |
| Environment | <code>$CODER_NOTIFICATIONS_DISPATCH_TIMEOUT</code> |
| YAML | <code>notifications.dispatch-timeout</code> |
| YAML | <code>notifications.dispatchTimeout</code> |
| Default | <code>1m0s</code> |
How long to wait while a notification is being sent before giving up.
@@ -1249,6 +1249,117 @@ The intermediary SMTP host through which emails are sent.
The hostname identifying the SMTP server.
### --notifications-email-force-tls
| | |
| ----------- | ------------------------------------------------- |
| Type | <code>bool</code> |
| Environment | <code>$CODER_NOTIFICATIONS_EMAIL_FORCE_TLS</code> |
| YAML | <code>notifications.email.forceTLS</code> |
| Default | <code>false</code> |
Force a TLS connection to the configured SMTP smarthost.
### --notifications-email-auth-identity
| | |
| ----------- | ----------------------------------------------------- |
| Type | <code>string</code> |
| Environment | <code>$CODER_NOTIFICATIONS_EMAIL_AUTH_IDENTITY</code> |
| YAML | <code>notifications.email.emailAuth.identity</code> |
Identity to use with PLAIN authentication.
### --notifications-email-auth-username
| | |
| ----------- | ----------------------------------------------------- |
| Type | <code>string</code> |
| Environment | <code>$CODER_NOTIFICATIONS_EMAIL_AUTH_USERNAME</code> |
| YAML | <code>notifications.email.emailAuth.username</code> |
Username to use with PLAIN/LOGIN authentication.
### --notifications-email-auth-password
| | |
| ----------- | ----------------------------------------------------- |
| Type | <code>string</code> |
| Environment | <code>$CODER_NOTIFICATIONS_EMAIL_AUTH_PASSWORD</code> |
| YAML | <code>notifications.email.emailAuth.password</code> |
Password to use with PLAIN/LOGIN authentication.
### --notifications-email-auth-password-file
| | |
| ----------- | ---------------------------------------------------------- |
| Type | <code>string</code> |
| Environment | <code>$CODER_NOTIFICATIONS_EMAIL_AUTH_PASSWORD_FILE</code> |
| YAML | <code>notifications.email.emailAuth.passwordFile</code> |
File from which to load password for use with PLAIN/LOGIN authentication.
### --notifications-email-tls-starttls
| | |
| ----------- | ---------------------------------------------------- |
| Type | <code>bool</code> |
| Environment | <code>$CODER_NOTIFICATIONS_EMAIL_TLS_STARTTLS</code> |
| YAML | <code>notifications.email.emailTLS.startTLS</code> |
Enable STARTTLS to upgrade insecure SMTP connections using TLS.
### --notifications-email-tls-server-name
| | |
| ----------- | ------------------------------------------------------ |
| Type | <code>string</code> |
| Environment | <code>$CODER_NOTIFICATIONS_EMAIL_TLS_SERVERNAME</code> |
| YAML | <code>notifications.email.emailTLS.serverName</code> |
Server name to verify against the target certificate.
### --notifications-email-tls-skip-verify
| | |
| ----------- | ------------------------------------------------------------ |
| Type | <code>bool</code> |
| Environment | <code>$CODER_NOTIFICATIONS_EMAIL_TLS_SKIPVERIFY</code> |
| YAML | <code>notifications.email.emailTLS.insecureSkipVerify</code> |
Skip verification of the target server's certificate (insecure).
### --notifications-email-tls-ca-cert-file
| | |
| ----------- | ------------------------------------------------------ |
| Type | <code>string</code> |
| Environment | <code>$CODER_NOTIFICATIONS_EMAIL_TLS_CACERTFILE</code> |
| YAML | <code>notifications.email.emailTLS.caCertFile</code> |
CA certificate file to use.
### --notifications-email-tls-cert-file
| | |
| ----------- | ---------------------------------------------------- |
| Type | <code>string</code> |
| Environment | <code>$CODER_NOTIFICATIONS_EMAIL_TLS_CERTFILE</code> |
| YAML | <code>notifications.email.emailTLS.certFile</code> |
Certificate file to use.
### --notifications-email-tls-cert-key-file
| | |
| ----------- | ------------------------------------------------------- |
| Type | <code>string</code> |
| Environment | <code>$CODER_NOTIFICATIONS_EMAIL_TLS_CERTKEYFILE</code> |
| YAML | <code>notifications.email.emailTLS.certKeyFile</code> |
Certificate key file to use.
### --notifications-webhook-endpoint
| | |
@@ -1265,7 +1376,7 @@ The endpoint to which to send webhooks.
| ----------- | --------------------------------------------------- |
| Type | <code>int</code> |
| Environment | <code>$CODER_NOTIFICATIONS_MAX_SEND_ATTEMPTS</code> |
| YAML | <code>notifications.max-send-attempts</code> |
| YAML | <code>notifications.maxSendAttempts</code> |
| Default | <code>5</code> |
The upper limit of attempts to send a notification.